Media
Injecting Bias in Text-To-Image Models via Composite-Trigger Backdoors
Naseh, Ali, Roh, Jaechul, Bagdasaryan, Eugene, Houmansadr, Amir
Recent advances in large text-conditional image generative models such as Stable Diffusion, Midjourney, and DALL-E 3 have revolutionized the field of image generation, allowing users to produce high-quality, realistic images from textual prompts. While these developments have enhanced artistic creation and visual communication, they also present an underexplored attack opportunity: the possibility of inducing biases by an adversary into the generated images for malicious intentions, e.g., to influence society and spread propaganda. In this paper, we demonstrate the possibility of such a bias injection threat by an adversary who backdoors such models with a small number of malicious data samples; the implemented backdoor is activated when special triggers exist in the input prompt of the backdoored models. On the other hand, the model's utility is preserved in the absence of the triggers, making the attack highly undetectable. We present a novel framework that enables efficient generation of poisoning samples with composite (multi-word) triggers for such an attack. Our extensive experiments using over 1 million generated images and against hundreds of fine-tuned models demonstrate the feasibility of the presented backdoor attack. We illustrate how these biases can bypass conventional detection mechanisms, highlighting the challenges in proving the existence of biases within operational constraints. Our cost analysis confirms the low financial barrier to executing such attacks, underscoring the need for robust defensive strategies against such vulnerabilities in text-to-image generation models.
Generate-then-Ground in Retrieval-Augmented Generation for Multi-hop Question Answering
Shi, Zhengliang, Zhang, Shuo, Sun, Weiwei, Gao, Shen, Ren, Pengjie, Chen, Zhumin, Ren, Zhaochun
Multi-Hop Question Answering (MHQA) tasks present a significant challenge for large language models (LLMs) due to the intensive knowledge required. Current solutions, like Retrieval-Augmented Generation, typically retrieve potential documents from an external corpus to read an answer. However, the performance of this retrieve-then-read paradigm is constrained by the retriever and the inevitable noise in the retrieved documents. To mitigate these challenges, we introduce a novel generate-then-ground (GenGround) framework, synergizing the parametric knowledge of LLMs and external documents to solve a multi-hop question. GenGround empowers LLMs to alternate two phases until the final answer is derived: (1) formulate a simpler, single-hop question and directly generate the answer; (2) ground the question-answer pair in retrieved documents, amending any wrong predictions in the answer. We also propose an instructional grounding distillation method to generalize our method into smaller models. Extensive experiments conducted on four datasets illustrate the superiority of our method.
UDA: A Benchmark Suite for Retrieval Augmented Generation in Real-world Document Analysis
Hui, Yulong, Lu, Yao, Zhang, Huanchen
The use of Retrieval-Augmented Generation (RAG) has improved Large Language Models (LLMs) in collaborating with external data, yet significant challenges exist in real-world scenarios. In areas such as academic literature and finance question answering, data are often found in raw text and tables in HTML or PDF formats, which can be lengthy and highly unstructured. In this paper, we introduce a benchmark suite, namely Unstructured Document Analysis (UDA), that involves 2,965 real-world documents and 29,590 expert-annotated Q&A pairs. We revisit popular LLM- and RAG-based solutions for document analysis and evaluate the design choices and answer qualities across multiple document domains and diverse query types. Our evaluation yields interesting findings and highlights the importance of data parsing and retrieval. We hope our benchmark can shed light and better serve real-world document analysis applications. The benchmark suite and code can be found at https://github.com/qinchuanhui/UDA-Benchmark.
Teach Better or Show Smarter? On Instructions and Exemplars in Automatic Prompt Optimization
Wan, Xingchen, Sun, Ruoxi, Nakhost, Hootan, Arik, Sercan O.
Large language models have demonstrated remarkable capabilities, but their performance is heavily reliant on effective prompt engineering. Automatic prompt optimization (APO) methods are designed to automate this and can be broadly categorized into those targeting instructions (instruction optimization, IO) vs. those targeting exemplars (exemplar selection, ES). Despite their shared objective, these have evolved rather independently, with IO recently receiving more research attention. This paper seeks to bridge this gap by comprehensively comparing the performance of representative IO and ES techniques, both isolation and combination, on a diverse set of challenging tasks. Our findings reveal that intelligently reusing model-generated input-output pairs obtained from evaluating prompts on the validation set as exemplars consistently improves performance over IO methods but is currently under-investigated. We also find that despite the recent focus on IO, how we select exemplars can outweigh how we optimize instructions, with ES strategies as simple as random search outperforming state-of-the-art IO methods with seed instructions without any optimization. Moreover, we observe synergy between ES and IO, with optimal combinations surpassing individual contributions. We conclude that studying exemplar selection as a standalone method and its optimal combination with instruction optimization remains a crucial aspect of APO and deserves greater consideration in future research, even in the era of highly capable instruction-following models.
Unsupervised Extraction of Dialogue Policies from Conversations
Sreedhar, Makesh Narsimhan, Rebedea, Traian, Parisien, Christopher
Dialogue policies play a crucial role in developing task-oriented dialogue systems, yet their development and maintenance are challenging and typically require substantial effort from experts in dialogue modeling. While in many situations, large amounts of conversational data are available for the task at hand, people lack an effective solution able to extract dialogue policies from this data. In this paper, we address this gap by first illustrating how Large Language Models (LLMs) can be instrumental in extracting dialogue policies from datasets, through the conversion of conversations into a unified intermediate representation consisting of canonical forms. We then propose a novel method for generating dialogue policies utilizing a controllable and interpretable graph-based methodology. By combining canonical forms across conversations into a flow network, we find that running graph traversal algorithms helps in extracting dialogue flows. These flows are a better representation of the underlying interactions than flows extracted by prompting LLMs. Our technique focuses on giving conversation designers greater control, offering a productivity tool to improve the process of developing dialogue policies.
Detecting AI-Generated Text: Factors Influencing Detectability with Current Methods
Fraser, Kathleen C., Dawkins, Hillary, Kiritchenko, Svetlana
Large language models (LLMs) have advanced to a point that even humans have difficulty discerning whether a text was generated by another human, or by a computer. However, knowing whether a text was produced by human or artificial intelligence (AI) is important to determining its trustworthiness, and has applications in many domains including detecting fraud and academic dishonesty, as well as combating the spread of misinformation and political propaganda. The task of AI-generated text (AIGT) detection is therefore both very challenging, and highly critical. In this survey, we summarize state-of-the art approaches to AIGT detection, including watermarking, statistical and stylistic analysis, and machine learning classification. We also provide information about existing datasets for this task. Synthesizing the research findings, we aim to provide insight into the salient factors that combine to determine how "detectable" AIGT text is under different scenarios, and to make practical recommendations for future work towards this significant technical and societal challenge.
Detecting Synthetic Lyrics with Few-Shot Inference
Labrak, Yanis, Meseguer-Brocal, Gabriel, Epure, Elena V.
In recent years, generated content in music has gained significant popularity, with large language models being effectively utilized to produce human-like lyrics in various styles, themes, and linguistic structures. This technological advancement supports artists in their creative processes but also raises issues of authorship infringement, consumer satisfaction and content spamming. To address these challenges, methods for detecting generated lyrics are necessary. However, existing works have not yet focused on this specific modality or on creative text in general regarding machine-generated content detection methods and datasets. In response, we have curated the first dataset of high-quality synthetic lyrics and conducted a comprehensive quantitative evaluation of various few-shot content detection approaches, testing their generalization capabilities and complementing this with a human evaluation. Our best few-shot detector, based on LLM2Vec, surpasses stylistic and statistical methods, which are shown competitive in other domains at distinguishing human-written from machine-generated content. It also shows good generalization capabilities to new artists and models, and effectively detects post-generation paraphrasing. This study emphasizes the need for further research on creative content detection, particularly in terms of generalization and scalability with larger song catalogs. All datasets, pre-processing scripts, and code are available publicly on GitHub and Hugging Face under the Apache 2.0 license.
Generative AI Misuse: A Taxonomy of Tactics and Insights from Real-World Data
Marchal, Nahema, Xu, Rachel, Elasmar, Rasmi, Gabriel, Iason, Goldberg, Beth, Isaac, William
Generative, multimodal artificial intelligence (GenAI) offers transformative potential across industries, but its misuse poses significant risks. Prior research has shed light on the potential of advanced AI systems to be exploited for malicious purposes. However, we still lack a concrete understanding of how GenAI models are specifically exploited or abused in practice, including the tactics employed to inflict harm. In this paper, we present a taxonomy of GenAI misuse tactics, informed by existing academic literature and a qualitative analysis of approximately 200 observed incidents of misuse reported between January 2023 and March 2024. Through this analysis, we illuminate key and novel patterns in misuse during this time period, including potential motivations, strategies, and how attackers leverage and abuse system capabilities across modalities (e.g. image, text, audio, video) in the wild.
I Watched TMZ's Bizarre Bennifer Documentary. It's, Uh, Saying a Lot.
For weeks now, we've been waiting for the other Timberland-inspired Manolo to drop. About a month ago, news outlets first reported that Jennifer Lopez and Ben Affleck's marriage was in trouble--that the two, in fact, had not been seen together in 47 days. No official announcement of a separation or divorce has followed, but the updates we have gotten--he moved out; they're only sometimes wearing their rings--support the narrative that bad news is on its way. I know that it's a sign of my celebrity brain rot that I can't help but see grim parallels between the fragmentary updates on the state of their marriage and the trickle of information about the state of Jimmy Carter's health. When a newsworthy event is likely to happen--for example, the imminent death of a 99-year-old former president--journalistic outlets have a practice of prewriting the news, to have it ready to go when the time comes.
Liberal media outlets 'running cover' for Biden by calling viral clips 'cheap fakes,' critics say
There has been an avalanche of coverage recently from liberal news outlets on so-called "cheap fakes," the term being used by both the media and the White House to describe viral clips of President Biden that critics say show signs of his cognitive decline. Biden's age has been the subject of intense scrutiny in recent days, with the president facing accusations of freezing and wandering off at various events showcased online by Republicans. One prominent example was footage showing Biden stepping away from other world leaders at the G-7 Summit to give a thumbs up to parachutists off-camera, prompting Italian Prime Minister Giorgia Meloni to corral him back to the group for a photo-op. "Selective editing of video and putting spin on interpretations of events has been going on in American politics for a long time," DePauw University journalism professor Jeffrey McCall said. "What has been surprising, however, is how eager the establishment media have been to parrot the White House spin, trying to dismiss concerns about Biden's capabilities as just cheap fake editing and razzle-dazzle."